Isaca AAISM Practice Test Questions and Exam Dumps Part20 Q381-400

View Full Isaca AAISM Exam Dumps and Practice Test Dumps

 

Question 381. Which activity BEST helps an organization identify AI systems that may be operating without proper authorization?

  1. Reviewing the enterprise AI inventory against approved procurement and deployment records
  2. Increasing the number of AI models in development
  3. Removing inactive users from unrelated applications
  4. Reviewing only systems that have experienced incidents

Correct Answer: 1. Reviewing the enterprise AI inventory against approved procurement and deployment records

Explanation:

Unauthorized AI systems can create significant governance, privacy, security, and compliance exposure because they may operate without appropriate risk assessment, ownership, monitoring, or approval. Comparing the enterprise AI inventory with procurement records, application inventories, deployment records, and other authoritative sources can help identify systems that are missing from governance processes. The objective is to establish organizational visibility and determine whether each system has an accountable owner and appropriate authorization. Reviewing only systems involved in incidents is reactive and may miss significant risks. Increasing development activity or modifying unrelated user accounts does not provide effective discovery. Regular reconciliation of inventories therefore helps identify shadow AI and ensures systems are brought into the appropriate governance lifecycle.

Question 382. What is the PRIMARY purpose of defining escalation criteria for AI-related risks?

  1. To ensure every issue is handled by the same employee
  2. To establish when a risk requires additional authority, expertise, or intervention
  3. To eliminate the need for risk assessments
  4. To prevent management from accepting any risk

Correct Answer: 2. To establish when a risk requires additional authority, expertise, or intervention

Explanation:

AI risks can vary significantly in severity, business impact, regulatory significance, and urgency. Clearly defined escalation criteria establish when an issue should move from operational management to specialized risk personnel, senior management, a governance committee, or another authorized decision-maker. Criteria may consider factors such as potential harm, regulatory exposure, affected individuals, security impact, model performance deterioration, or risk appetite thresholds. Escalation does not mean that management must reject every risk. Some risks may be accepted by authorized personnel when they fall within established tolerance. Effective escalation processes therefore improve accountability and ensure that significant AI risks receive the appropriate level of attention and decision-making authority.

Question 383. An AI system is producing increasingly inconsistent results after a major change in its operating environment. What should be evaluated FIRST?

  1. Whether the environmental change may have affected model assumptions or performance
  2. Whether all historical governance documents should be deleted
  3. Whether the organization should immediately purchase a new model
  4. Whether monitoring should be permanently disabled

Correct Answer: 1. Whether the environmental change may have affected model assumptions or performance

Explanation:

A major operating-environment change can affect assumptions that supported the original AI validation and risk assessment. Changes may involve data sources, infrastructure, user behavior, integrations, business processes, external dependencies, or other environmental conditions. When model outputs become inconsistent after such a change, management should first determine whether there is a relationship between the environmental change and the observed behavior. This may require reviewing monitoring data, model inputs, dependencies, validation evidence, and recent changes. Immediate replacement may be premature because the underlying cause has not yet been established. Governance records should be preserved, and monitoring should remain active because it provides evidence needed for investigation, remediation, and future reassessment.

Question 384. Which control MOST effectively supports separation of duties during AI model deployment?

  1. Allowing developers to approve their own production releases
  2. Giving one administrator responsibility for development, validation, and deployment
  3. Requiring independent approval before production deployment
  4. Removing deployment records after successful implementation

Correct Answer: 3. Requiring independent approval before production deployment

Explanation:

Segregation of duties reduces the risk that one individual can develop, validate, approve, and deploy an AI model without independent oversight. Requiring an appropriately independent approval before production deployment creates an additional control point where evidence can be reviewed and potential weaknesses identified. Depending on the organization’s risk profile, development, validation, approval, and deployment responsibilities may be distributed across different individuals or teams. Allowing developers to approve their own releases creates a conflict of interest and reduces control effectiveness. Removing deployment records also eliminates important evidence. Independent approval should be supported by documented criteria, traceable evidence, and clearly assigned responsibilities.

Question 385. Which information is MOST important to include in documentation for an AI system’s intended use?

  1. Only the model’s programming language
  2. Only the vendor’s marketing description
  3. Only the system’s storage location
  4. The business purpose, expected users, decision context, and significant limitations

Correct Answer: 4. The business purpose, expected users, decision context, and significant limitations

Explanation:

Documentation of intended use should provide enough context to determine how an AI system is authorized to operate and what boundaries apply. Important information includes the business purpose, expected users, types of decisions or recommendations supported, relevant data, operating context, significant limitations, and potentially prohibited or restricted uses. This information helps governance personnel determine whether actual usage remains within the approved scope. Technical details such as programming language and storage location can be useful but do not by themselves establish intended use. Vendor marketing material may also be incomplete or promotional. Clear intended-use documentation supports risk assessment, user training, monitoring, change management, and future reassessment when the system’s purpose or environment changes.

Question 386. What is the PRIMARY reason to maintain evidence linking an AI model version to its validation results?

  1. To prove that every model will produce identical outputs
  2. To establish which validated model was approved for a particular deployment
  3. To eliminate the need for monitoring
  4. To prevent all future model changes

Correct Answer: 2. To establish which validated model was approved for a particular deployment

Explanation:

Model validation evidence is meaningful only when the organization can determine which specific model version was evaluated. Linking model versions to validation results creates traceability between testing and the artifact actually approved for use. Without this connection, a later or modified model could be deployed while the organization continues relying on validation results associated with an earlier version. Effective traceability can include model identifiers, version numbers, validation dates, datasets, test results, approval records, and deployment information. This control does not guarantee identical outputs or eliminate monitoring. Instead, it provides evidence that the model operating in production corresponds to the model that was evaluated and authorized under the organization’s governance process.

Question 387. Which approach BEST addresses privacy risk when AI training data contains more personal information than is necessary for the approved purpose?

  1. Collecting additional personal information
  2. Making the dataset available to all developers
  3. Applying data minimization and removing or reducing unnecessary personal information
  4. Disabling all data-quality checks

Correct Answer: 3. Applying data minimization and removing or reducing unnecessary personal information

Explanation:

Data minimization reduces privacy exposure by limiting personal information to what is necessary for the legitimate and approved AI purpose. If training data contains unnecessary personal information, the organization should evaluate whether those fields can be removed, masked, aggregated, anonymized, or otherwise reduced while preserving required functionality. Broad access by developers increases exposure and does not address the underlying issue. Collecting additional information can increase privacy risk rather than reduce it. Data-quality checks should remain active because quality and privacy controls serve different objectives. Data minimization should be incorporated into AI data governance from collection and preparation through training, testing, deployment, retention, and disposal, with documented justification for sensitive data elements that remain necessary.

Question 388. An AI vendor uses subcontractors to process organizational data. What should governance personnel verify?

  1. Whether subcontractor activities are covered by appropriate contractual and oversight requirements
  2. Whether subcontractors can change the organization’s risk appetite
  3. Whether subcontractors can approve organizational AI deployments
  4. Whether all subcontractor employees have unrestricted access

Correct Answer: 1. Whether subcontractor activities are covered by appropriate contractual and oversight requirements

Explanation:

Third-party AI risk can extend beyond the primary vendor when subcontractors process data, provide infrastructure, operate model components, or perform other material services. Governance personnel should therefore determine which subcontractors are involved, what responsibilities they perform, what information they can access, and whether appropriate contractual protections and oversight mechanisms apply. Relevant requirements may include security controls, privacy obligations, confidentiality, incident notification, audit rights, data handling, geographic restrictions, and change notification. Subcontractors should not be given unrestricted access simply because they support the vendor. Nor should they determine the organization’s risk appetite or approve its deployments. Effective third-party governance requires visibility into material dependencies throughout the provider’s supply chain.

Question 389. What should management do when an AI control repeatedly fails despite previous corrective actions?

  1. Close the finding without further analysis
  2. Increase the reporting frequency without changing the control
  3. Ignore the issue if no incident has occurred
  4. Perform root-cause analysis and reassess whether the control design is appropriate

Correct Answer: 4. Perform root-cause analysis and reassess whether the control design is appropriate

Explanation:

Repeated control failure suggests that previous remediation may have addressed symptoms rather than the underlying cause. Management should investigate why the control continues to fail and determine whether the problem involves control design, ownership, implementation, resources, system dependencies, training, monitoring, or unrealistic requirements. Root-cause analysis helps distinguish between isolated execution errors and structural weaknesses. If the control itself is poorly designed, simply repeating the same corrective action is unlikely to produce sustainable improvement. Governance personnel should document the analysis, assign accountable owners, establish corrective actions, and monitor effectiveness after implementation. Repeated findings should also be considered when evaluating residual risk and determining whether escalation to senior management is necessary.

Question 390. Which activity BEST demonstrates that AI governance is integrated into the organization’s risk management process?

  1. AI risks are identified, assessed, treated, monitored, and reported through established enterprise risk processes
  2. AI risks are maintained only by developers
  3. AI risks are reviewed only after security incidents
  4. AI risks are excluded from enterprise reporting

Correct Answer: 1. AI risks are identified, assessed, treated, monitored, and reported through established enterprise risk processes

Explanation:

Integration with enterprise risk management helps ensure that AI risks receive consistent treatment alongside other significant organizational risks. This means AI risks should be identified, assessed according to defined criteria, assigned owners, treated through appropriate controls, monitored over time, and escalated or reported according to established governance requirements. Maintaining AI risks exclusively within development teams can create fragmented oversight and may prevent senior management from understanding enterprise-level exposure. Reactive review after incidents is also insufficient because risk management should be preventive as well as responsive. Effective integration allows management to consider AI risks in strategic planning, risk appetite decisions, resource allocation, assurance activities, and enterprise reporting.

Question 391. Which factor should MOST influence the level of human oversight required for an AI system?

  1. The number of developers who built the system
  2. The potential impact and risk associated with AI-supported decisions
  3. The programming language used by the model
  4. The physical size of the model’s infrastructure

Correct Answer: 2. The potential impact and risk associated with AI-supported decisions

Explanation:

Human oversight should be proportionate to the potential consequences of AI-supported decisions. Systems that influence high-impact decisions, sensitive activities, safety-related processes, or significant rights and interests generally require stronger review and intervention mechanisms than low-impact applications. The required level of oversight may include pre-decision review, approval, exception handling, ongoing monitoring, or the ability to override AI recommendations. Technical characteristics such as programming language or infrastructure size do not by themselves determine the appropriate governance level. The number of developers is similarly unrelated to the potential consequences of an AI decision. Risk-based human oversight helps ensure that AI systems remain subject to appropriate accountability while allowing lower-risk applications to operate with proportionate controls.

Question 392. What is the PRIMARY purpose of an AI risk register?

  1. To document and track identified AI risks, owners, treatments, and status
  2. To store source code for every model
  3. To replace all technical monitoring
  4. To guarantee that no AI risk will occur

Correct Answer: 1. To document and track identified AI risks, owners, treatments, and status

Explanation:

An AI risk register provides a structured record of identified risks and supports ongoing risk management. Typical information can include the risk description, affected system, risk owner, inherent risk, existing controls, treatment plan, residual risk, target dates, status, and escalation information. Maintaining this information allows management to monitor whether identified risks are being treated effectively and whether important actions remain overdue. A risk register does not replace technical monitoring, testing, or other control activities, and it cannot guarantee that risks will not occur. Its value comes from creating accountability and visibility across the AI portfolio. It also provides evidence for governance committees, management reporting, audits, and periodic risk reassessments.

Question 393. Which condition should generally trigger reassessment of an AI system’s governance requirements?

  1. A routine user login
  2. A minor formatting change in an unrelated report
  3. A material change in the system’s purpose, data, model, or operating environment
  4. A scheduled employee vacation

Correct Answer: 3. A material change in the system’s purpose, data, model, or operating environment

Explanation:

Governance requirements should be reassessed when changes could materially affect the assumptions, risks, controls, or approved purpose of an AI system. Examples include significant changes to the model, training or operational data, intended business use, user population, geographic scope, external provider, integrations, or operating environment. Such changes can introduce new privacy, security, fairness, performance, compliance, or operational risks. Routine events unrelated to the system’s risk profile generally do not require a governance reassessment. Organizations should define material-change triggers in their governance procedures so that responsible personnel know when to initiate additional risk assessment, validation, approval, documentation, or control changes before continuing or expanding use.

Question 394. Which practice BEST supports accountability for decisions made using AI recommendations?

  1. Allowing users to remain anonymous
  2. Assigning responsibility only to the AI model
  3. Avoiding documentation of decision outcomes
  4. Maintaining identifiable decision ownership and appropriate supporting records

Correct Answer: 4. Maintaining identifiable decision ownership and appropriate supporting records

Explanation:

AI systems may provide recommendations, classifications, predictions, or other outputs, but organizations still need clear accountability for consequential decisions. Identifiable decision ownership establishes who is responsible for reviewing the AI output, applying relevant policies, exercising judgment, and making or approving the final decision. Supporting records can include the AI system and version used, relevant inputs, output, human review, decision rationale, approvals, and applicable exceptions. Assigning responsibility to the model is not an effective accountability mechanism because the model cannot exercise organizational authority. Avoiding documentation also makes investigations and audits difficult. Strong governance therefore connects AI-assisted decisions to authorized individuals or functions and maintains sufficient evidence to support accountability.

Question 395. Why should organizations evaluate the portability of critical AI workloads when relying on an external provider?

  1. To ensure every provider uses identical infrastructure
  2. To reduce dependence on a single provider and improve resilience
  3. To eliminate all vendor management requirements
  4. To prevent any model from being updated

Correct Answer: 2. To reduce dependence on a single provider and improve resilience

Explanation:

Portability can reduce operational and strategic dependence on a single AI provider. If a critical provider experiences prolonged service disruption, changes pricing or functionality, introduces unacceptable model changes, or becomes unavailable, the organization’s ability to move workloads can affect business continuity. Portability considerations may include data formats, model artifacts, interfaces, contractual rights, documentation, alternative providers, migration procedures, and technical dependencies. Portability does not require providers to use identical infrastructure and does not eliminate vendor management. It also does not mean that model updates should be prohibited. Instead, understanding portability and exit requirements helps management evaluate concentration and lock-in risk and develop practical continuity options for critical AI services.

Question 396. What is the PRIMARY purpose of maintaining AI governance training records?

  1. To demonstrate that relevant personnel received required governance education
  2. To guarantee that employees will never make mistakes
  3. To replace competency assessments
  4. To eliminate the need for policy communication

Correct Answer: 1. To demonstrate that relevant personnel received required governance education

Explanation:

Training records provide evidence that personnel who have AI-related responsibilities received the education required by organizational policy or governance standards. Depending on their roles, employees may need training covering acceptable AI use, data handling, privacy, security, risk escalation, human oversight, documentation, or other governance requirements. Records can help management identify gaps, support compliance reviews, and determine whether refresher training is necessary. Training records do not guarantee that employees will never make mistakes, so organizations may also need competency checks, monitoring, and supervision. Maintaining records should complement rather than replace policy communication. Effective training governance links role requirements to appropriate learning activities and retains evidence that those activities were completed.

Question 397. Which approach BEST supports transparency when communicating the limitations of an AI system to users?

  1. Hiding known limitations to encourage adoption
  2. Providing clear information about relevant limitations, uncertainty, and appropriate use
  3. Claiming that the system is always accurate
  4. Allowing users to discover limitations only through incidents

Correct Answer: 2. Providing clear information about relevant limitations, uncertainty, and appropriate use

Explanation:

Transparency requires users to have sufficient information to understand how an AI system should and should not be used. Communicating relevant limitations, uncertainty, known failure conditions, data constraints, and appropriate-use boundaries helps users make informed judgments about AI outputs. This is particularly important where inaccurate or misleading outputs could cause significant consequences. Hiding limitations can encourage inappropriate reliance, while claims of perfect accuracy create unrealistic expectations. Users should not have to discover important limitations through incidents. Transparency should be proportionate to the system’s risk and may include documentation, user guidance, interface notices, training, and escalation procedures. Clear communication supports responsible use and helps maintain appropriate human oversight.

Question 398. What should an organization consider when determining whether an AI governance exception is acceptable?

  1. Whether granting the exception is convenient for the development team
  2. Whether the exception can remain undocumented
  3. The risk created, compensating controls, authorization authority, duration, and review requirements
  4. Whether similar exceptions were previously ignored

Correct Answer: 3. The risk created, compensating controls, authorization authority, duration, and review requirements

Explanation:

Governance exceptions should be managed through a controlled process rather than informal agreements. Management should understand why the exception is needed, what risk it creates, whether compensating controls can reduce that risk, who has authority to approve it, how long it remains valid, and when it must be reviewed or closed. Documentation provides evidence of the decision and allows future reviewers to determine whether the exception remains justified. Convenience alone is not sufficient justification, and undocumented exceptions weaken accountability. Previous informal exceptions do not establish that a new exception is acceptable. A risk-based exception process helps organizations balance legitimate operational needs with governance requirements while ensuring that deviations remain visible, authorized, time-bound, and appropriately monitored.

Question 399. Which activity BEST helps an organization identify emerging AI governance risks before they become significant issues?

  1. Conducting horizon scanning and periodically evaluating new developments
  2. Waiting for incidents to reveal new risks
  3. Reviewing only last year’s audit findings
  4. Discontinuing monitoring of external developments

Correct Answer: 1. Conducting horizon scanning and periodically evaluating new developments

Explanation:

Horizon scanning helps organizations identify emerging AI risks arising from changes in technology, regulations, threat patterns, business practices, vendor capabilities, and societal expectations. Early identification gives management more time to assess potential impacts and determine whether policies, controls, training, contracts, or risk assessments need to change. Waiting for incidents is reactive and may expose the organization to avoidable harm. Historical audit findings remain useful but cannot fully identify future developments. Effective horizon scanning should be structured and connected to governance decision-making, with relevant developments evaluated for materiality and translated into appropriate actions when necessary. This supports proactive governance and helps ensure that the AI risk management program remains responsive to a changing environment.

Question 400. Which outcome MOST clearly indicates that an AI governance framework is operating effectively?

  1. Governance activities are performed only when auditors request evidence
  2. AI risks are managed consistently, accountability is clear, controls are monitored, and identified weaknesses are addressed
  3. All AI systems are managed exclusively by technical staff
  4. Governance documentation exists but is not used operationally

Correct Answer: 2. AI risks are managed consistently, accountability is clear, controls are monitored, and identified weaknesses are addressed

Explanation:

An effective AI governance framework should operate as an active management process rather than as documentation created primarily for audits. Evidence of effectiveness includes consistent risk identification and treatment, clear ownership, appropriate decision rights, functioning controls, monitoring, escalation of significant issues, and timely remediation of identified weaknesses. Governance should influence how AI systems are approved, deployed, monitored, changed, and retired. Technical personnel have important responsibilities, but enterprise governance should also involve business, risk, legal, privacy, security, compliance, and other appropriate functions. Simply having policies or records does not demonstrate effectiveness. The strongest evidence comes from governance processes being consistently applied and producing measurable improvements in accountability, risk management, control performance, and organizational resilience.